Show filters
131 Total Results
Displaying 31-40 of 131
Sort by:
Attacker Value
Unknown
CVE-2021-22880
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.
0
Attacker Value
Unknown
CVE-2020-8264
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
0
Attacker Value
Unknown
CVE-2020-8166
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
0
Attacker Value
Unknown
CVE-2020-8185
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
0
Attacker Value
Unknown
CVE-2020-8163
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
0
Attacker Value
Unknown
CVE-2020-8165
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
0
Attacker Value
Unknown
CVE-2020-8167
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
0
Attacker Value
Unknown
CVE-2020-8164
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
0
Attacker Value
Unknown
CVE-2020-8162
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
0
Attacker Value
Unknown
CVE-2020-8151
Disclosure Date: May 12, 2020 (last updated February 21, 2025)
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
0